Impact
A race condition in cockpit-files allows a local unprivileged attacker that can write to a chosen directory to replace a freshly created directory with a symbolic link before the ownership change function (chown) is executed. This maneuver redirects the ownership change to the target of the symlink, giving the attacker control over the ownership of an arbitrary file. The attacker can thus gain unintended file ownership, potentially reading protected data or modifying critical system files, which compromises confidentiality and integrity of the system.
Affected Systems
The flaw affects Red Hat Enterprise Linux 10 and 9, specifically the cockpit-files component. No specific version numbers are listed, so any installation of cockpit-files on these operating systems should be considered vulnerable until an update is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 6, indicating moderate severity. EPSS is not available, so the estimated probability of exploitation is unknown, though the attack requires local execution and the ability to create files in a directory that cockpit-files can later chown. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully exploits the race might redirect ownership to an arbitrary file, potentially leading to information disclosure or unauthorized file modification.
OpenCVE Enrichment